MALICIOUS — fojusatu.pdf
MALICIOUS — fojusatu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e931154fd0b24c35c309e6ea573906ad8c05b9fca5bd3da1d06e4a743105d98f - SHA-1:
c67a95a1edd40af3c6835b10c4c98badc972fbfd - MD5:
78e80b9e9521c5410c3f33c079d8b449 - ssdeep:
1536:gkKltjincKeJ6pYTS35FaSYUmIdzEzWRIUYWCpOViunPWs02Lo3pU9CR3:wlIcK5pg25FaSYm+62UpViqRwqi - TLSH:
T1F538CFF36187DD4CBB8B8B4364FA25A8C04AD3CC6161EA9044CCB96CD5BC57EBE20650 - Submitted as: fojusatu.pdf
- File type: pdf · Size: 82254 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://schoonhovensvrouwenkoor.nl/ckfinder/userfiles/files/48285499658.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://krisoc.ru/uplcv?utm_term=games+that+give+free+robux, https://tucsonhomewindowtint.com/wp-content/plugins/super-forms/uploads/php/files/c97c4ea29689da45381f5aa30daceef3/16630146171.pdf, https://amgaa.org/temp/files/55980948995.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://krisoc.ru/uplcv?utm_term=games+that+give+free+robux
- https://tucsonhomewindowtint.com/wp-content/plugins/super-forms/uploads/php/files/c97c4ea29689da45381f5aa30daceef3/16630146171.pdf
- https://amgaa.org/temp/files/55980948995.pdf
- http://cetinelektrik.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/161357f3097272---68294057566.pdf
- http://schoonhovensvrouwenkoor.nl/ckfinder/userfiles/files/48285499658.pdf
- http://www.verneteco.com/ckfinder/userfiles/files/nufeta.pdf
- http://www.absolutecateringla.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613924ab9e907---86544552225.pdf
- http://mojahotels.com/ckfinder/userfiles/files/98852202275.pdf
- http://ajivikafinance.com/userfiles/file/fekodex.pdf
- http://resetimpianti.it/reset/public/file/46024445140.pdf
- http://damutech.kz/upload/2021/09files/2109020647584697340md2v.pdf
- http://woodlander.sk/grafika/file/xigekoxuxetowatufiwaje.pdf
- http://luyenthidhcanhsat.com/Images_upload/files/jedenuzumu.pdf
- https://na-nule.ru/wp-content/plugins/super-forms/uploads/php/files/hbpsc1ntp3docv28r6mq3n1fj5/11277126503.pdf
- https://momsgardenfoods.com/ckfinder/userfiles/files/kitibajotakupeluvatuj.pdf
- http://kasintorn.com/images/upload/files/39857455368.pdf
- https://ntc-container.com/upload/files/wojofibopob.pdf
- https://seikai.jp/free_images/files/83614293326.pdf
- http://twtime.com/uploads/files/202109011911147333.pdf
- http://hk-sai.com/ckfinder/userfiles/files/nepijogulatujo.pdf
- http://everestlodgelukla.com/userfiles/file/65049437312.pdf
- http://asja.ua/userfiles/file/32115413646.pdf
- http://frankifoto.com/uploads/pages/files/fopelu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- krisoc.ru
- tucsonhomewindowtint.com
- amgaa.org
- schoonhovensvrouwenkoor.nl
- www.verneteco.com
- www.absolutecateringla.com
- mojahotels.com
- ajivikafinance.com
- resetimpianti.it
- luyenthidhcanhsat.com
- na-nule.ru
- momsgardenfoods.com
- kasintorn.com
- ntc-container.com
- seikai.jp
- twtime.com
- hk-sai.com
- everestlodgelukla.com
- asja.ua
- frankifoto.com
- www.w3.org
- purl.org
- ns.adobe.com
- cetinelektrik.com.tr
- damutech.kz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report